CYBER SECURITY – GUIDANCE
oNvoe mrcoyrbee crl osuedcsurity
Leading experts in cyber security have produced an authoritative guide that could help factories
and process plants better protect their resources. The guide’s project lead, Awais Rashid, explains more
T By Steed Webzell
he Cyber Security Body of
follow. As the rst guide of its kind,
Knowledge (CyBOK), funded
CyBOK, whose scope is drawn in the
by the UK’s National Cyber
infographic below, will also help to expand
Security Programme and
the capabilities of those tasked with
initiated by the National
tackling the security challenges of an
Cyber Security Centre (NCSC), has
increasingly connected commercial world.
been created in a bid to ll the skills
And there is little doubt of its necessity
gap and provide consistent knowledge
– a 2018 report by the Washingtonbased
and advice for people to based Center for Strategic
International Studies estimated that
cybercrime costs the world economy
close to £481 billion a year
(www.is.gd/uferik).
To set about creating CyBOK, a project
team of internationally-recognised
scholars undertook an extensive exercise
involving the mapping and analysis
of relevant texts, as well as a range
of community consultations via UK
workshops, an online survey, interviews
and position papers. Once these
exercises were complete, the 19 top-level
knowledge areas (KAs) collated from the
consultations and other various inputs
were distilled and used to inform the
scope of CyBOK. The KAs are essentially
documents that comprehensively explore
the strengths, limitations and implications
of issues such as: risk management and
governance; law and regulations; privacy
and online rights; malware and criminal
behaviours; and securing mobile and web
technologies.
“Cyber security as a eld is evolving
rapidly, as most people will probably
determine from the regular mainstream
news stories involving major breaches,”
says Awais Rashid, the project’s lead
and professor of cyber security at
the University of Bristol’s Faculty of
Engineering. “Until CyBOK, there was
no singular space that consolidated
foundational knowledge on this subject.
Although cyber security is a hot topic,
there is wide variation in the quality
of published information. If you’re
46 www.operationsengineer.org.uk Autumn 2020
/uferik)
/www.operationsengineer.org.uk